Datto EDR Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Datto EDR Tools
dattoedr_ · 96 tools · Free 61 · Pro 35
Endpoint detection and response, built as Infocyte HUNT - the product's own addresses still say infocyte.com, which is not a typo. The base address is your own instance on that domain; a datto.com address is refused. The credential is a single API token minted in the product UI, and it stops working one year after creation with no renewal path, so a 401 is often the ordinary end of a token's life. Paging is offset and limit carried inside a JSON filter parameter, capped at 1000 by the vendor. Forensic reads are scoped to a box - a rollup over 7, 30 or 90 days - and with no box id given the tenant's Global Last 7 days box is used. Most of the write surface reaches live customer machines: restoring an isolated host is treated as destructive, while creating or publishing a rule is not, because no code runs on an endpoint.
All connector tools · Datto EDR setup guide
Datto EDR tool groups
- Platform — 13 tools
- Alerts — 5 tools
- Endpoints & Estate — 16 tools
- Scan Credentials — 3 tools
- Scans & Scheduling — 9 tools
- Response Actions — 6 tools
- Forensic Results — 16 tools
- Threat Intelligence & Triage — 10 tools
- Vulnerabilities & Compliance — 4 tools
- Detection Rules & Extensions — 14 tools
Platform
dattoedr_count_records details
dattoedr_count_records details
[Datto EDR] Count the rows of any Datto EDR collection matching a filter, without fetching them. Returns {"count": N}. USE THIS FIRST on the big forensic tables: Datto EDR warns that wide, unfiltered queries strain its database, and a count tells you whether a filter is narrow enough before you ask for the rows. Valid collections are the ones the other tools read — Alerts, Agents, ScanProcessInstances, ScanHosts and so on; the error message lists them all if you pass one that is not recognized. This count is NOT scoped to an aggregation box: the forensic tools fall back to your Global Last 7 Days box when you give them no box id, so a count of a forensic table can be far larger than what those tools return. Put the same boxId in this filter to compare like with like.
dattoedr_get_box details
dattoedr_get_box details
[Datto EDR] Get one aggregation box by id, from dattoedr_list_boxes. Returns the box's scope and window along with its summary counters.
dattoedr_get_job details
dattoedr_get_job details
dattoedr_get_task details
dattoedr_get_task details
[Datto EDR] Get one task's status by id — the follow-up call for EVERY scan and containment action on this connector, because none of them returns its result. Status is created, active, completed, cancelled or failed, alongside a percentage and elapsed seconds. For per-host detail use dattoedr_list_task_items, and for the messages beneath each host use dattoedr_list_task_item_progress. Once the task completes, the findings themselves are in dattoedr_list_scan_hosts, dattoedr_list_extension_details and dattoedr_list_alerts, keyed by the scan id.
dattoedr_get_user_activity details
dattoedr_get_user_activity details
dattoedr_get_version details
dattoedr_get_version details
[Datto EDR] Get the Datto EDR instance and API version. The cheapest call on the connector — use it to confirm the instance address and token are working before running anything expensive.
dattoedr_list_boxes details
dattoedr_list_boxes details
[Datto EDR] List the aggregation boxes. A box is a pre-computed rollup of results over one scope and one window — Global or a single target group, across 7, 30 or 90 days — and its id is what scopes most forensic and object reads. START HERE before using the forensic tools: pass the box id you want to dattoedr_list_process_instances and its siblings, or they fall back to the Global Last 7 Days box and the result silently means 'the last week'.
dattoedr_list_jobs details
dattoedr_list_jobs details
[Datto EDR] List Datto EDR's own background jobs — the platform's internal work, not the user tasks a scan or a containment action creates. For those use dattoedr_list_tasks.
dattoedr_list_task_item_progress details
dattoedr_list_task_item_progress details
[Datto EDR] List the progress messages beneath one task item — the running commentary for a single endpoint. The deepest level of the task chain; use it when a host is stuck or failed and the item's own status does not say why. Filter on taskItemId, from dattoedr_list_task_items.
dattoedr_list_task_items details
dattoedr_list_task_items details
[Datto EDR] List a task's per-host items — one row per endpoint the task touched, with that endpoint's own outcome. Filter on userTaskId to scope it to one task, or the whole table comes back.
dattoedr_list_tasks details
dattoedr_list_tasks details
[Datto EDR] List user tasks. Every scan, network enumeration, containment action and offline import on this connector creates one, so this is where to look for work that is running or recently finished. Filter on type to separate scans from response actions.
dattoedr_list_user_activities details
dattoedr_list_user_activities details
[Datto EDR] List the audit log — who did what in Datto EDR and when. Use it to evidence a containment action for a client, or to answer 'who isolated that machine'.
dattoedr_list_users details
dattoedr_list_users details
[Datto EDR] List the users of this Datto EDR instance. Most objects carry a createdBy or updatedBy id rather than a name — this is how those ids become people. Note that a Datto EDR API token inherits the rights of the user who created it, so this list is also what decides how far any token can reach.
Alerts
dattoedr_get_alert details
dattoedr_get_alert details
[Datto EDR] Get one alert by id, from dattoedr_list_alerts. Returns the full detection record. To pull the forensic evidence behind it, take the scan id from the alert and pass it to the forensic tools such as dattoedr_list_process_instances.
dattoedr_get_report details
dattoedr_get_report details
[Datto EDR] Get one report's metadata by id, from dattoedr_list_reports. The report file itself is not available through this API.
dattoedr_list_alerts details
dattoedr_list_alerts details
[Datto EDR] List alerts raised in the LAST 30 DAYS — threat name and weight, the host and file involved, and whether Datto EDR judged it malicious. This is the connector's main read and the natural starting point for a morning triage sweep or ticket enrichment. IMPORTANT: alerts older than 30 days are NOT here — Datto EDR moves them to a separate archive, so use dattoedr_list_archived_alerts for anything beyond a month. Alerts come from four sources (rule, reputation, compliance and extension); filter on sourceType to separate them.
dattoedr_list_archived_alerts details
dattoedr_list_archived_alerts details
[Datto EDR] List alerts OLDER than 30 days. Datto EDR keeps only the last 30 days in its live alert table and moves everything before that here, so this is the tool for a quarterly review, an annual report, or any question about a period further back than a month. Use dattoedr_list_alerts for the current month, and read both when a window straddles the 30-day boundary.
dattoedr_list_reports details
dattoedr_list_reports details
[Datto EDR] List the reports Datto EDR has generated, with their type, scope and generation time. Returns report METADATA — the report files themselves are downloaded from the Datto EDR interface, not through this API.
Endpoints & Estate
dattoedr_create_controller_group details
dattoedr_create_controller_group details
[Datto EDR] Create a controller group. Additive — it defines the grouping and reaches no endpoint.
dattoedr_create_discovery_query details
dattoedr_create_discovery_query details
[Datto EDR] Create an agentless discovery query — an IP range, hostname pattern, LDAP query or AWS query defining where to look for machines. This only DEFINES the query; it does not run it and touches nothing on the network until an enumeration is dispatched with dattoedr_enumerate_target_group.
dattoedr_create_target_group details
dattoedr_create_target_group details
[Datto EDR] Create a target group. Purely additive — it defines an empty grouping and touches no endpoint. Nothing is scanned until a scan is dispatched against it.
dattoedr_delete_address details
dattoedr_delete_address details
[Datto EDR] Delete one discovered address and its history. Irreversible; the address reappears only if discovery finds it again.
dattoedr_delete_addresses details
dattoedr_delete_addresses details
[Datto EDR] Delete SEVERAL discovered addresses at once, by id. Bulk and irreversible — the discovery history for each address goes with it. List what you are about to remove with dattoedr_list_addresses first. To delete a single address use dattoedr_delete_address instead.
dattoedr_delete_archived_target_group details
dattoedr_delete_archived_target_group details
[Datto EDR] Permanently delete an ARCHIVED target group — one already removed from active use but still held for its history. This is the second and final deletion; the historical data goes with it.
dattoedr_delete_controller_group details
dattoedr_delete_controller_group details
[Datto EDR] Delete a controller group. Any agentless scanning that depended on those collectors stops working.
dattoedr_delete_discovery_query details
dattoedr_delete_discovery_query details
[Datto EDR] Delete a discovery query. Future enumerations of its target group will no longer look where it looked, so machines it used to find stop being discovered.
dattoedr_delete_target_group details
dattoedr_delete_target_group details
[Datto EDR] Delete a target group. This CASCADES: the group's discovered addresses and the scan data held against it go with it. Check what the group contains with dattoedr_list_addresses before deleting.
dattoedr_get_agent details
dattoedr_get_agent details
[Datto EDR] Get one agent by id, from dattoedr_list_agents. Returns the machine's full agent record.
dattoedr_list_addresses details
dattoedr_list_addresses details
[Datto EDR] List the addresses discovery has found in a target group, with whether each one is reachable and when it was last accessed. This is the agentless counterpart to dattoedr_list_agents — machines Datto EDR knows about but does not necessarily have an agent on.
dattoedr_list_agents details
dattoedr_list_agents details
[Datto EDR] List the installed Datto EDR agents, with each machine's hostname, operating system, version and last check-in. THE reconciliation read: this is how you answer 'is every endpoint I bill for actually protected and reporting in'. Filter on the authorized and active flags to separate machines that are enrolled from machines that are alive.
dattoedr_list_controller_groups details
dattoedr_list_controller_groups details
dattoedr_list_discovery_queries details
dattoedr_list_discovery_queries details
[Datto EDR] List the agentless discovery queries defined on this instance — IP range, hostname, LDAP and AWS queries that find machines to scan. Listing them is read-only; a query only reaches the network when an enumeration is dispatched against its target group.
dattoedr_list_target_groups details
dattoedr_list_target_groups details
[Datto EDR] List target groups — the logical groupings of hosts Datto EDR scans and reports against. A target group id is what scopes a group scan, a network enumeration and most aggregation boxes, so this is usually the first call before dispatching any scan.
dattoedr_uninstall_agent details
dattoedr_uninstall_agent details
[Datto EDR] REMOVE the Datto EDR agent from one or more live endpoints. The machines lose detection and response coverage immediately and stay unprotected until someone reinstalls the agent by hand. There is no undo and no test mode. Confirm which machines are in scope before running this — pass agent ids from dattoedr_list_agents rather than a broad selector.
Scan Credentials
dattoedr_create_scan_credential details
dattoedr_create_scan_credential details
[Datto EDR] Store a new scan credential in Datto EDR. The request body carries a REAL, WORKING domain or SSH credential — this writes a live secret into the platform, and anything that can dispatch a scan can then use it against the customer's machines. Marked destructive for that reason rather than for its verb. Prefer entering credentials in the Datto EDR interface, where the secret never travels through a tool call.
dattoedr_delete_scan_credential details
dattoedr_delete_scan_credential details
[Datto EDR] Delete a stored scan credential. Any agentless scan or schedule that relied on it begins failing, and the secret cannot be recovered — it has to be re-entered.
dattoedr_list_scan_credentials details
dattoedr_list_scan_credentials details
[Datto EDR] List the credentials Datto EDR holds for agentless scanning — their names, types and where they are used. METADATA ONLY: the passwords and keys themselves are never returned by this API.
Scans & Scheduling
dattoedr_create_scan_record details
dattoedr_create_scan_record details
[Datto EDR] Create an empty scan record to hold the results of an offline survey import. Reaches no endpoint and scans nothing — it only creates the container. NOTE: this operation is the one path in the Datto EDR connector that StackJack has not seen the vendor's own client call, so its address is inferred from the model name rather than observed. Treat a 404 here as 'this path may be wrong' rather than 'the record does not exist', and report it.
dattoedr_create_scheduled_job details
dattoedr_create_scheduled_job details
[Datto EDR] Create a RECURRING scan on a cron schedule. Marked destructive because the effect is live dispatch, just deferred: from now on this scan reaches every endpoint in the target group on every run, without anyone approving it again. Check the existing schedule with dattoedr_list_scheduled_jobs first, and prefer off-hours cron expressions on production networks.
dattoedr_delete_scheduled_job details
dattoedr_delete_scheduled_job details
[Datto EDR] Delete a scheduled scan. The recurring sweep stops, so the target group is no longer scanned on that cadence until something replaces it — check with the customer before removing a schedule that underpins their coverage commitments.
dattoedr_enumerate_target_group details
dattoedr_enumerate_target_group details
[Datto EDR] Run network discovery for a target group — an ACTIVE SWEEP of the customer's own infrastructure using that group's discovery queries. It generates real network traffic and can trip intrusion-detection systems, so agree the window with the customer before running it against a production network. Returns a task id; follow it with dattoedr_get_task, then read what it found with dattoedr_list_addresses.
dattoedr_get_scan details
dattoedr_get_scan details
[Datto EDR] Get one scan by id, from dattoedr_list_scans. Returns the scan's own record — what was scanned, when, and the totals it produced.
dattoedr_list_scans details
dattoedr_list_scans details
[Datto EDR] List scans, with each one's target group, timing and result counts. A scan id from here is the key into the forensic tables — pass it in the where filter of dattoedr_list_scan_hosts, dattoedr_list_process_instances and their siblings to see what that scan found.
dattoedr_list_scheduled_jobs details
dattoedr_list_scheduled_jobs details
[Datto EDR] List the scheduled scans on this instance, with each one's cron expression, target group and scan options. Read this before adding a schedule — overlapping recurring scans of the same group are a common cause of unexplained load on a customer's machines.
dattoedr_scan_target details
dattoedr_scan_target details
[Datto EDR] Launch a forensic scan of a SINGLE endpoint by hostname or IP address. Live dispatch: the machine begins collecting processes, modules, drivers, autostarts, accounts and network connections immediately. The target must have an active agent, or an accessible address entry in the target group. Returns a task id — follow it with dattoedr_get_task. This is the read-only investigative counterpart to the containment tools; it collects evidence and changes nothing on the machine.
dattoedr_scan_target_group details
dattoedr_scan_target_group details
[Datto EDR] Launch a forensic scan of an ENTIRE target group — every endpoint in it, right now. This is live dispatch: agents begin collecting, agentless hosts are reached over the network, and a large group means real load on the customer's machines. Scope it first with dattoedr_list_target_groups and dattoedr_list_addresses. Returns a task id, not results: follow it with dattoedr_get_task, then read the findings from dattoedr_list_scan_hosts and dattoedr_list_alerts. To scan a single machine use dattoedr_scan_target instead.
Response Actions
dattoedr_collect_evidence details
dattoedr_collect_evidence details
[Datto EDR] Collect forensic evidence from an endpoint — data files, event logs and related artifacts — and copy it to the storage bucket configured in Datto EDR. This MOVES CUSTOMER DATA OFF THE MACHINE to a third-party location, so check the destination and the customer's data-handling agreement before running it. The extension name is required rather than assumed: StackJack has no vendor source naming the evidence-collection extension, so pass the exact name from your instance's extension list (see dattoedr_list_extensions). Returns a task id.
dattoedr_isolate_host details
dattoedr_isolate_host details
[Datto EDR] ISOLATE an endpoint — cut it off the network so it can reach only Datto EDR and other security tools. The machine stops serving users, stops reaching file shares, line-of-business applications and the internet, and stays that way until someone restores it with dattoedr_restore_host. Isolating a domain controller, a hypervisor or a shared server takes a customer's service down. Confirm the exact hostname before running this, and be sure it is the machine you mean. Returns a task id; follow it with dattoedr_get_task.
dattoedr_kill_process details
dattoedr_kill_process details
[Datto EDR] TERMINATE a process on a live endpoint, selected by name, SHA1 hash, process id or image path. The process stops immediately, with no save and no warning to the user at the keyboard — killing the wrong one loses work or takes a service down. Prefer the SHA1 or the full path over a bare name, because a name can match several processes. Returns a task id; follow it with dattoedr_get_task, and confirm the outcome with dattoedr_list_extension_details.
dattoedr_recover_files details
dattoedr_recover_files details
[Datto EDR] Copy named files off an endpoint to the recovery point configured in Datto EDR (an S3 bucket, FTP server or file share). This MOVES CUSTOMER DATA to that destination, and the files may be malicious or may contain sensitive content — check the destination and the customer's agreement first. The extension name is required rather than assumed: StackJack has no vendor source naming the file-recovery extension, so pass the exact name from dattoedr_list_extensions. Returns a task id.
dattoedr_restore_host details
dattoedr_restore_host details
[Datto EDR] RESTORE an isolated endpoint to the network. Marked destructive even though it undoes an isolation: putting a machine back on the network during a live incident re-exposes everything it can reach, so it needs the same deliberate approval as isolating it. Confirm the machine is actually clean before running this. Returns a task id; follow it with dattoedr_get_task.
dattoedr_run_extension details
dattoedr_run_extension details
[Datto EDR] Run ANY named extension on a live endpoint. An extension is a script Datto EDR executes on the machine, so this is an open-ended remote execution verb: what it does depends entirely on the extension, and it can do anything the extension's author wrote. Use the specific tools instead where one exists — dattoedr_isolate_host, dattoedr_restore_host, dattoedr_kill_process — and reach for this one only for extensions with no dedicated tool. Read the extension first with dattoedr_get_extension_latest_version so you know what you are running. Returns a task id; the output lands in dattoedr_list_extension_details.
Forensic Results
dattoedr_get_extension_detail details
dattoedr_get_extension_detail details
[Datto EDR] Read a single extension execution result. Datto EDR serves this from a separate single-record view alongside the list view, and the two are genuinely different endpoints rather than duplicates. Use dattoedr_list_extension_details when you want several results and this when you want exactly one; narrow it with the where filter.
dattoedr_list_account_instances details
dattoedr_list_account_instances details
[Datto EDR] List the local and domain accounts a scan found on the machines it examined. Use it to spot an account an attacker created, or a local administrator nobody knew about. For the same data grouped by machine use dattoedr_list_account_instances_by_host.
dattoedr_list_account_instances_by_host details
dattoedr_list_account_instances_by_host details
[Datto EDR] List account findings rolled up per machine — the same data as dattoedr_list_account_instances, grouped by host. Use this one when the question is 'which machines does this account exist on', and the ungrouped one when the question is about the accounts themselves.
dattoedr_list_application_instances details
dattoedr_list_application_instances details
[Datto EDR] List the installed applications a scan found across the estate. Doubles as a software inventory, and pairs with dattoedr_list_application_advisories to turn 'what is installed' into 'what is installed and vulnerable'.
dattoedr_list_artifact_instances details
dattoedr_list_artifact_instances details
[Datto EDR] List the forensic artifacts a scan collected — the traces left behind by activity on the machine, rather than the running code itself. Useful for reconstructing what happened after the fact.
dattoedr_list_autostart_instances details
dattoedr_list_autostart_instances details
[Datto EDR] List the autostart and persistence entries a scan found — scheduled tasks, services, run keys and the rest of the ways code arranges to run again after a reboot. This is where you confirm an attacker established persistence, and what you check before declaring a machine clean.
dattoedr_list_box_extension_instances details
dattoedr_list_box_extension_instances details
[Datto EDR] List extension executions already aggregated across a box's whole window. Cheaper than paging dattoedr_list_extension_instances when the question is about a period rather than a single scan — for example 'how many times did we isolate a host this month'.
dattoedr_list_connection_instances details
dattoedr_list_connection_instances details
[Datto EDR] List the network connections a scan observed, with the process at each end. Use it to find command-and-control traffic, and to work out which other machines a compromised host was talking to.
dattoedr_list_driver_instances details
dattoedr_list_driver_instances details
[Datto EDR] List the kernel drivers a scan found loaded. A malicious driver runs below most defenses, so an unrecognized or unsigned entry here is worth escalating even when everything else looks clean.
dattoedr_list_extension_details details
dattoedr_list_extension_details details
[Datto EDR] List extension execution results WITH THEIR OUTPUT — success flag, threat verdict and the messages the extension wrote. This is how you confirm a containment action actually worked: after dattoedr_isolate_host or dattoedr_kill_process completes, filter here on the scan id from the task to read what the endpoint reported back.
dattoedr_list_extension_instances details
dattoedr_list_extension_instances details
[Datto EDR] List extension executions — which extension ran, on which machine, and whether it succeeded. This is the summary of every containment action and custom script run; for the output each one produced use dattoedr_list_extension_details.
dattoedr_list_memory_scan_instances details
dattoedr_list_memory_scan_instances details
[Datto EDR] List what Datto EDR's memory scan found. This is where fileless and in-memory-only threats appear — malware that leaves nothing on disk shows up here and nowhere else.
dattoedr_list_module_instances details
dattoedr_list_module_instances details
[Datto EDR] List the modules and libraries loaded into processes during a scan. Use it to find code injected into a legitimate process — the parent process looks clean in dattoedr_list_process_instances, and the malicious payload is here.
dattoedr_list_process_instances details
dattoedr_list_process_instances details
[Datto EDR] List the processes a scan found running, with each one's image path, hash and threat verdict. The first table to read during an incident: it is where a malicious executable shows up. Filter on scanId or hostname, and on threatStatus to see only what Datto EDR flagged.
dattoedr_list_scan_hosts details
dattoedr_list_scan_hosts details
[Datto EDR] List the per-host results of scans — one row per machine, with its operating system, IP, the threat verdict Datto EDR reached and the totals it collected. START HERE when reading scan results: this is the summary, and the other forensic tools are the detail beneath it. Filter on scanId to scope to one scan.
dattoedr_list_script_instances details
dattoedr_list_script_instances details
[Datto EDR] List the scripts a scan found on the machines it examined. PowerShell, batch and shell scripts are a common attacker foothold, and one dropped somewhere unusual is worth reading in full.
Threat Intelligence & Triage
dattoedr_add_comment details
dattoedr_add_comment details
[Datto EDR] Add a note to an object in Datto EDR. Purely additive — it records text against the object and changes nothing else, which makes it the safe way to leave an audit trail of what an investigation concluded. Attach it with relatedId: a SHA1 for a file, an object id for anything else.
dattoedr_create_flag details
dattoedr_create_flag details
[Datto EDR] Create a triage flag. Additive — it adds a label to the palette and changes nothing that already exists. Note that a flag's weight influences Datto EDR's scoring once analysts start applying it.
dattoedr_delete_flag details
dattoedr_delete_flag details
[Datto EDR] Delete a triage flag. Findings that carried it lose that label and its scoring weight, so a flag underpinning a tuning decision should be retired rather than deleted.
dattoedr_get_file_dwell_time details
dattoedr_get_file_dwell_time details
[Datto EDR] Get one dwell-time record by its own id, from dattoedr_list_file_dwell_times. The record id here is a GUID; the file it describes is identified by a SHA1 in its fileRepId field.
dattoedr_get_file_reputation details
dattoedr_get_file_reputation details
[Datto EDR] Look up a file's reputation by its SHA1 hash — Datto EDR's verdict on whether that exact binary is known good, unknown or malicious. The direct answer to 'is this hash bad'. Note the identifier: this one takes a 40-character SHA1 hash, not the GUIDs the rest of the connector uses. To find out how long the file has been in the estate, pair it with dattoedr_list_file_dwell_times.
dattoedr_get_flag details
dattoedr_get_flag details
dattoedr_list_comments details
dattoedr_list_comments details
[Datto EDR] List the notes analysts have left on objects — the running commentary on an investigation. Filter on relatedId to see the notes for one object; note that relatedId is a SHA1 when the note is attached to a file and a GUID when it is attached to anything else.
dattoedr_list_file_dwell_times details
dattoedr_list_file_dwell_times details
[Datto EDR] List how long files have been present in the estate — first seen, last seen, and on how many machines. Dwell time is the question that turns a detection into an incident scope: a bad file first seen this morning is contained, and one first seen eight months ago is not. Filter on fileRepId, which is a SHA1 hash.
dattoedr_list_flags details
dattoedr_list_flags details
dattoedr_replace_flag details
dattoedr_replace_flag details
[Datto EDR] REPLACE a triage flag wholesale. This is a replace, not an update: every field you leave out of the body is cleared, not preserved. Read the flag first with dattoedr_get_flag and send back the complete object with your changes applied. Changing a flag's weight also changes how everything already carrying it is scored.
Vulnerabilities & Compliance
dattoedr_get_cve details
dattoedr_get_cve details
[Datto EDR] Get the detail of one CVE — the detection rules that cover it, its weakness classifications and its references. Take the CVE id from dattoedr_list_application_advisories.
dattoedr_list_application_advisories details
dattoedr_list_application_advisories details
[Datto EDR] List the advisories linking installed applications to known CVEs — the bridge between 'what software is on this estate' and 'which of it is vulnerable'. Good vCIO and quarterly-review material. Pair it with dattoedr_list_application_instances to find which machines are affected, and dattoedr_get_cve for the detail of a specific vulnerability.
dattoedr_list_compliance_result_items details
dattoedr_list_compliance_result_items details
[Datto EDR] List the individual checks inside compliance results — which control passed, which failed, and why. Filter on complianceResultId to scope to one machine's run, and on passed to list only the failures, which is the list a remediation plan is built from.
dattoedr_list_compliance_results details
dattoedr_list_compliance_results details
[Datto EDR] List compliance scan results — one row per machine per compliance run, with its overall outcome. For the individual checks beneath a result use dattoedr_list_compliance_result_items.
Detection Rules & Extensions
dattoedr_create_extension details
dattoedr_create_extension details
[Datto EDR] Import or create an extension — a script Datto EDR will execute on customer endpoints. This is the highest-risk operation on the connector: the script can do whatever its author wrote, on any machine it is later run against, and it is not marked destructive for its verb but for what it makes possible afterwards. Only import scripts you have read and trust, and review them in the Datto EDR interface rather than through an agent wherever you can.
dattoedr_create_extension_global details
dattoedr_create_extension_global details
[Datto EDR] Create a global variable that extensions read at run time. Destructive because of what the value does rather than what the write does: extensions consume these while executing on customer endpoints, so a variable naming a storage destination or an exception list changes the behavior of code running on live machines.
dattoedr_create_rule details
dattoedr_create_rule details
[Datto EDR] Create a detection rule. Additive and versioned — nothing existing is changed and no code runs on an endpoint, which is why this is not marked destructive. It does change what Datto EDR alerts on from now on, so a rule that matches too broadly produces noise across every customer on the instance. Test the logic against a narrow scope first.
dattoedr_delete_extension details
dattoedr_delete_extension details
[Datto EDR] Delete an extension. Anything that relied on it stops working — including the response actions, which resolve their extension by name at dispatch time, so deleting the isolation extension breaks dattoedr_isolate_host for this instance. Check what uses it before removing it.
dattoedr_delete_rule details
dattoedr_delete_rule details
[Datto EDR] Delete a detection rule. Datto EDR stops detecting whatever the rule covered, across every machine, from that moment — this REMOVES SECURITY COVERAGE and the gap is silent. Prefer disabling a noisy rule or publishing a narrower version over deleting it.
dattoedr_get_extension details
dattoedr_get_extension details
[Datto EDR] Get one extension by id, from dattoedr_list_extensions. Returns its record; for the script itself use dattoedr_get_extension_latest_version.
dattoedr_get_extension_latest_version details
dattoedr_get_extension_latest_version details
[Datto EDR] Get an extension's CURRENT SCRIPT and its checksum. Read this before running an extension with dattoedr_run_extension — an extension is code that executes on a customer's endpoint, and this is the only way to see what it will do.
dattoedr_get_rule details
dattoedr_get_rule details
[Datto EDR] Get one detection rule by id, from dattoedr_list_rules. Returns the rule's record; for its current body and checksum use dattoedr_get_rule_latest_version.
dattoedr_get_rule_latest_version details
dattoedr_get_rule_latest_version details
[Datto EDR] Get a detection rule's CURRENT BODY and its checksum. The body is not carried on the rule's own record, so this is the only way to read what a rule actually matches on. Read this before publishing a new version — it is the version you are about to supersede.
dattoedr_list_extension_globals details
dattoedr_list_extension_globals details
dattoedr_list_extensions details
dattoedr_list_extensions details
[Datto EDR] List the extensions loaded in this instance — both the collection scripts that gather extra data during a scan and the response scripts that act on an endpoint. USE THIS to find the exact extension name the response tools need, particularly dattoedr_collect_evidence and dattoedr_recover_files, which take the name as an argument.
dattoedr_list_rules details
dattoedr_list_rules details
[Datto EDR] List the detection rules on this instance, with their names and current state. The rule BODY is not on these rows — read it with dattoedr_get_rule_latest_version. Start here when tuning noisy alerts: find the rule an alert's sourceType points at, then read its body before changing anything.
dattoedr_publish_extension_version details
dattoedr_publish_extension_version details
[Datto EDR] Publish a new version of an existing extension — new code that will execute on customer endpoints from the next run onward. Same risk as creating one: anything that runs the extension after this point runs YOUR version. Read the current script with dattoedr_get_extension_latest_version first.
dattoedr_publish_rule_version details
dattoedr_publish_rule_version details
[Datto EDR] Publish a new version of an existing detection rule. Not destructive because Datto EDR keeps every prior version and nothing is overwritten — but the new version takes effect immediately, so read the current one with dattoedr_get_rule_latest_version first and know what you are replacing in practice.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team